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MEMORANDUM FOR: Chief, Management and Assessment Staff, DDA 


FROM: | 
cting Director of Security 
SUBJECT: Report to the Senate Select Committee 
(Intelligence) on Community Information 
Handling 
REFERENCE: Memorandum from Intelligence Information 


Handling Committee dated 31 January 1978, 
same subject 


1. Action Requested: None; this memorandum is for your 
information only. 


2. Background: Appropriate components of the Office of 
Security have reviewed subject report, which is proposed for 
submission to the Senate Select Committee on Intelligence on 
or before 11 February. The Office of Security has also had 
an opportunity to review the draft comments on subject report 
prepared by the Office of Data Processing (ODP) on 6 February 
1978, 


3. Staff Position: The Office of Security is in general 
agreement, except as noted below, with the comments prepared 
by the Office of Data Processing. It is suggested, however, 
that the ODP comments be expanded as follows: 


a. It is almost unbelievable that a report, 
scheduled for submission to the Senate Select 
Committee on Intelligence is disseminated for 
Community coordination only a few days before its 
intended transmission. The organizational policy 
and procedural proposals contained in the report 
have such far reaching implementation effects that 
the report deserves thorough and detailed coordina- 
tion; this coordination should indeed consider 
options available with reference to solving the 
problems the report details. 
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b. Annex C to subject report announces the 
establishment of a Community Information Systems 
Office (CISO). While it is not clear how large 
this component would be, Annex C describes a 
relatively wide mission. The Office of Security 
is particularly concerned that the component would 
encompass a Security and Privacy Standards Branch, 
which presumably would function as a focal point 
for Community computer security policy and 
Standards. 


The DCI Security Committee has a subcommittee 
devoted to computer security policy development 
at the present time. While it might be profitable 
to transfer this function to the proposed CISO, a 
move in this direction should not be pursued sunm- 
marily in the submission of subject report, 
especially as already noted without detailed 
Community coordination. 


c. The Office of Security concurs in the ODP 
recommendation that Annexes A, B, and C be for- 
warded to the Senate Select Committee for 
Intelligence, although we are reticent to support 
the transmittal of Annex C at all. Our concurrence 
in the ODP recommendation is qualified to the 
extent that all reference to a computer security 
function in the CISO should be deleted along with 
the identification of the Security and Privacy 
Standards Branch. On the other hand, we would 
have no objection to adding to the brief covering 
memorandum, suggested by ODP, a statement that 
further review of information handling activities 
in the Community might suggest the need for a 
computer security focal point in the CISO in STATINTL 
addition to the functions of the DCI Security 
Committee in this area 


Att 
Draft comments by 
ODP, dtd 6 Feb 78 
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6 February 1978 - _ 
t 
REFERENCE: Memo for IHC Members, from Chairman IHC, dtd ; 
-31 Jan. 1978, Same Subject, (IHC/M 78-03) : 
a Comments regarding referenced report are contained — 


in the following paragraphs and an ODP recommendation is made 
in the last paragraph. 


2% The reference has been reviewed by key members of 

the ODP staff and they are seriously concerned that insufficient 
time has been allowed to perform an indepth review of a report 
with such far-reaching implications. Such organizational and 
procedural proposals which have not been developed in collabora- 
tion with the members of the Intelligence Community should not 
be forwarded to a Congressional Committee until they have been ae 
coordinated with and agreed to by Community members. 


3. . It is inappropriate to send an organizational charter, 
Annex D, to Congress before it has been signed. 


4. The covering report and Annex E are confusing, 
inconsistent, and need drastic revision. It is not clear whether 
the Community Information Systems Office (CISO) is a staff or — 
a line organization. In Annex C it is more clearly a staff 
organization performing logical staff functions such as monitor- 
ing, reviewing, coordinating, advising, guiding, etc., while in 
the covering report and Annex E the CISO is depicted as perform- 
ing line functions such as designing, planning, developing I 
ALPE NeCLvess etc. 


5. The line functions eablected in the report and Ronee 

E would require an unnecessary duplication of technical staffs | 
of the Community members. P 

a : | 


6. . There are a sufficient number of discrepancies between 
the report and the Annexes that they should: not go forward with- 
out the full coordination of Community members and a full under- 
standing and acceptance of the procedures being proposed. This 
can only be accomplished by meeting with the drafters of the 
report so that queStions can be answered and acceptable procedures 
developed, as needed. 
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Te Annexes A, B and C are acceptable with some minor 
changes. The minor changes are listed in the attachment. 


8. ODP recommends that Annexes A, B, and C be forwarded aH 
to the Senate Select Committee (Intelligence) with a brief 
covering memo stating essentially the following: 


We know we have problems and have formed an 
organization to coordinate and monitor ADP 
activities in a Community context. The 
problems are described in Annexes A and B 
and the charter for the new organization is 
in Annex C. We are currently developing 
procedures for planning and coordinating 
activities. Our goals for the first year 
are: 


a. Establish CISO as a central planning 
organization in February 1978 as a part 
of the DCI's Resource Management Staff. 


db, Review annual NFIP resource request and 
-identify ADP-T issues needing DCI = © 
resolution. ze 


ec. Begin a formal and continuous dialogue with 
ADP-T offices in the Intelligence Community 
as well as program managers to keep abreast 
of operating systems, systems under develop- 
ment, and new ADP initiatives. 


d. Respond to Congressional needs for ADP-T 
information as. required. Begin identifying 
and examining major FY-79~84 issues as 

previously requested by SSCI. 


e. Undertake selected studies and technical 
evaluations in problem areas in support 
of resource management decision making. 


£'s Undertake actions to evaluate the feasibility 
of a "Community Information Handling System 
(CIHS)." : 


We will report to you in one year. on our progress. 


es: 
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ODP Recommended Changes to Memorandum Dated 31 January 1978 


from Chairman IHC, subject: Report to the Senate Select 
Committee (Intelligence) on Community Information Handling 


: Annex A 
Page ; 
2 _.. For the line entry starting with CIA/SAFE: 
change 1) "CIA/SAFE" to "SAFE"; 
change 2) "CIA/Support" to ores 
change 3) "CIA" to "DIA/DIA". 

2 “Delete the line entry starting with DIA/SAFE. 

18 ' The average age of Model 360/67 is listed as . 
1.2 years. The CIA 360/67 was installed in 1969. 
Recommend the average age figure be verified. 

Annex B 
No recommendations. 
“Annex Cc 
C-2 | ‘Pifth line - change "carry out". to. "coordinate". 
C-2 , In footnote (x) ~ delete ", as defined in Annex a", 
C-8 Para. 2 under FUNCTIONS - change "To design and 


establish" to "To establish the aaa for 
and monitor the development of". 


C-11 It is not. clear what the Contractor Support functions 
of the Community Planning Division are. It is 
believed they should be: 


Coordinate planning for Contractor Support. 
Coordinate contract monitoring and administration. 


c-14 Para. 3 under FUNCTIONS - Change “develop” to 
"coordinate". 
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